nerdexam
Isaca

CRISC · Question #37

Which of the following is PRIMARILY a risk management responsibly of the first line of defense?

The correct answer is A. Implementing risk treatment plans. The first line of defense is primarily responsible for the day-to-day management of risks, including the implementation of risk treatment plans. This involves operational activities to manage and control risks within their specific business units.

Submitted by ashley.k· Apr 18, 2026Governance

Question

Which of the following is PRIMARILY a risk management responsibly of the first line of defense?

Options

  • AImplementing risk treatment plans
  • BValidating the status of risk mitigation efforts
  • CEstablishing risk policies and standards
  • DConducting independent reviews of risk assessment results

How the community answered

(69 responses)
  • A
    88% (61)
  • B
    1% (1)
  • C
    4% (3)
  • D
    6% (4)

Why each option

The first line of defense is primarily responsible for the day-to-day management of risks, including the implementation of risk treatment plans. This involves operational activities to manage and control risks within their specific business units.

AImplementing risk treatment plansCorrect

The first line of defense, comprising operational management and staff, is directly responsible for managing risks inherent in their day-to-day activities and processes. This includes implementing the controls and actions defined in risk treatment plans to keep risks within acceptable limits, ensuring operational adherence to risk policies.

BValidating the status of risk mitigation efforts

Validating the status of risk mitigation efforts is typically a responsibility of the second line of defense (e.g., risk management function) or even the third line (audit).

CEstablishing risk policies and standards

Establishing risk policies and standards is a strategic responsibility typically belonging to the second line of defense (e.g., dedicated risk function) or senior management.

DConducting independent reviews of risk assessment results

Conducting independent reviews of risk assessment results is a function of the third line of defense (internal audit) to provide assurance on the effectiveness of the first and second lines.

Concept tested: Three lines of defense model

Topics

#Risk Management#Three Lines of Defense#First Line of Defense#Governance

Community Discussion

No community discussion yet for this question.

Full CRISC Practice